Authentication Bypass Vulnerability in Woffice by Envato Security Team
CVE-2024-43234

9.8CRITICAL

Key Information:

Vendor
WordPress
Status
Vendor
CVE Published:
16 December 2024

Summary

The CVE-2024-43234 vulnerability is classified as an authentication bypass vulnerability that affects the Woffice theme developed by the Envato Security Team. This flaw enables attackers to bypass security measures, allowing unauthorized access to sensitive areas without proper authentication. The vulnerability impacts versions of Woffice ranging from n/a to 5.4.14, putting users at risk of potential account takeovers and data compromises. It is crucial to address this vulnerability promptly by updating to the latest version of Woffice to mitigate any associated risks.

Affected Version(s)

Woffice <= 5.4.14

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Rafie Muhammad (Patchstack)
.